141
|
- |
|
-
|
-
|
A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the ar…
New
|
CWE-22
Path Traversal
|
CVE-2024-11210
|
2024-11-15 00:15 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
142
|
7.5 |
HIGH
Network
-
|
-
|
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
New
|
CWE-20
Improper Input Validation
|
CVE-2022-2232
|
2024-11-15 00:15 |
2024-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
143
|
5.5 |
MEDIUM
Local
|
razormist
|
student_record_management_system
|
A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Main Menu. The manipulati…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2024-11097
|
2024-11-15 00:14 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
144
|
6.1 |
MEDIUM
Network
|
opensuse
|
mirrorcache
|
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the …
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-49505
|
2024-11-15 00:13 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
145
|
9.8 |
CRITICAL
Network
dotnetzip.semverd_project
|
dotnetzip.semverd
|
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability onl…
New
|
CWE-22
Path Traversal
|
CVE-2024-48510
|
2024-11-15 00:04 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
146
|
5.4 |
MEDIUM
Network
|
apple
|
iphone_os ipados watchos visionos tvos macos safari
|
The issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, watchOS 11.1, visionOS 2.1, macOS Sequoia 15.1, Safari 18.1. Pr…
Update
|
NVD-CWE-noinfo
|
CVE-2024-44296
|
2024-11-14 23:58 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
147
|
7.3 |
HIGH
Network
wppa
|
wp_photo_album_plus
|
The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This …
Update
|
CWE-94
Code Injection
|
CVE-2024-10958
|
2024-11-14 23:57 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
148
|
7.2 |
HIGH
Network
|
angeljudesuarez
|
construction_management_system
|
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
New
|
CWE-89
SQL Injection
|
CVE-2024-50972
|
2024-11-14 23:55 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
149
|
9.8 |
CRITICAL
Network
weechat
|
weechat
|
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_f…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-46613
|
2024-11-14 23:55 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
150
|
7.2 |
HIGH
Network
|
angeljudesuarez
|
construction_management_system
|
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.
New
|
CWE-89
SQL Injection
|
CVE-2024-50971
|
2024-11-14 23:54 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|